Metasploit provide some commands to extend the usage of meterpreter. We will describe here under the usage of screenshot, screenspy and screengrab.
First of all you require a valid meterpreter session on a Windows box to use these extensions.
- screenshot
This stdapi command allow you to create a screen shot from the current Windows interactive desktop.
screenshot command could be used with these arguments :
-h : to display the help banner.
-p : The JPEG image file path. By default $HOME/[randomname].jpeg
-q : The JPEG image quality. By default ’50’.
-v : Automatically view the JPEG image, by default ‘true’.
data:image/s3,"s3://crabby-images/b3a8b/b3a8bf931c124e3a65ecda3fde3dfd2e4b46a4e4" alt="Metasploit Meterpreter screenshot Metasploit Meterpreter screenshot"
- (bg)run screenspy
Same as the screenshot command, but taking at regular interval screen shot from the current Windows interactive desktop. Require Firefox to visualize the screen shots. A HTML page, containing the new screen shot, will be updated regularly, into Firefox, every x seconds.
screenspy command could be used with these arguments :
-h : to display the help banner.
-d : The delay in seconds between each screen shot. By default 3 seconds.
-t : The time, in second, for the screenspy execution. By default 10 seconds.
-s : The targeted system, linux or windows. By default linux.
data:image/s3,"s3://crabby-images/27ef4/27ef49e07b19bcd92cb1a581208bcffb6ed65f40" alt="Metasploit Meterpreter screenspy Metasploit Meterpreter screenspy"
- screengrab
This espia command attempt to grab a screen shot from the current Windows interactive desktop.
screengrab command coulb be used with these arguments :
-h : to display the help banner.
data:image/s3,"s3://crabby-images/20b4c/20b4caa3538d5738fea6b9de957298b6bf1ccbdd" alt="Metasploit Meterpreter screengrab Metasploit Meterpreter screengrab"
data:image/s3,"s3://crabby-images/c4251/c425125b68e6d47c1ab53354743f75e996926c81" alt="Metasploit Meterpreter screengrab usage Metasploit Meterpreter screengrab usage"